In what is being hailed as the largest patch release since at least 2017, Microsoft’s January 2025 Patch Tuesday tackled a staggering 159 vulnerabilities—double the size of a typical January release. But while this patch rollout addresses a host of critical security issues, the reality is that many systems will remain vulnerable as they won’t have access to over half of the patches. This raises concerns for organizations that may not have the proper subscriptions or access to the latest updates.
For those unfamiliar, Patch Tuesday is a regular security update cadence by Microsoft, typically occurring on the second Tuesday of every month at 10 AM PST. On this day, Microsoft releases most of its security patches for Windows and other software. However, some updates are released on an as-needed basis, known as Out-of-Band (OOB) releases, for higher-priority vulnerabilities that cannot wait until the next scheduled patch.
This January’s Patch Tuesday update is a massive one, with Microsoft addressing 159 vulnerabilities across its ecosystem. Of these patches:
132 apply to Windows.
95 patches target end-of-life software, available only through a paid program.
19 patches affect Microsoft Office.
But here’s the catch: over half of these patches are accessible only to organizations that subscribe to Microsoft’s Extended Security Update (ESU) program. This program offers security updates for an additional three years after the end of a software’s supported life. Windows 10, for instance, will enter this paid support program starting in October of this year. Without this paid program, businesses will be unable to patch several critical vulnerabilities, leaving their systems at risk.
Of the vulnerabilities patched, three garnered a 9.8 CVE score, the highest possible severity rating. These critical vulnerabilities should be a top priority for any business to address. What's worse, 36% of the patches in this release dealt with Remote Code Execution (RCE) vulnerabilities, while 25% addressed Elevation of Privilege flaws. Together, these two categories made up more than 60% of the patches released.
RCE vulnerabilities are among the most dangerous, allowing attackers to take control of your systems remotely through the internet. Elevation of Privilege vulnerabilities, on the other hand, give attackers elevated access once they’ve already compromised a system, allowing them to wreak even more havoc.
With these vulnerabilities posing significant threats, here are three essential takeaways and next steps for organizations to secure their systems:
Don’t Put Windows on the Internet
Windows servers and services, such as Terminal Server offering Remote Desktop connections, are inherently insecure if exposed directly to the internet. They should always be secured behind a firewall or proxy service and only accessible after proper authentication, such as via a VPN. It’s essential to limit direct exposure to the internet. About 10% of CyberStreams clients come to us after being hacked because their services were exposed this way.
End-of-Life Software
Using unsupported, end-of-life Microsoft software makes your systems vulnerable unless you’re in the ESU program, which provides paid updates for up to 3 years. Eligible software includes Windows 7, Windows Server 2008/R2, 2012/R2, and others. If you're using older versions, upgrade immediately to avoid unnecessary risks.
Patch Management
Ensure that all your systems are receiving and successfully applying the latest patches. Many patches fail or cause issues during application. It’s crucial to establish a patch management strategy that guarantees all systems are regularly updated and protected against known vulnerabilities.
Microsoft’s January 2025 Mega-Patch Tuesday emphasizes the importance of timely patching, using supported software, and securing systems from remote exploitation. As these vulnerabilities evolve, businesses that fail to stay up-to-date with patches or use outdated systems may face significant security risks. Don’t let your organization be left vulnerable—take proactive steps now to ensure you're protected against the latest threats.
Hire us to set your IT strategy up for sustainable success.
Learn about our proven No-Nonsense approach.
Get an IT roadmap designed specifically for you.
Fearlessly grow your business.